video-scriptwriting
Warn
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to automatically perform local directory enumeration upon activation. It specifies running an
lscommand on hidden system directories, including~/.claude/skills/,~/.agent/skills/, and~/.agents/skills/, to detect companion skills. This constitutes unsolicited local environment probing.\n- [INDIRECT_PROMPT_INJECTION]: The skill identifies a vulnerability surface for indirect prompt injection via its interview-driven workflow.\n - Ingestion points: User responses are collected across a 30-question framework defined in
SKILL.mdandreferences/interview-questions.md.\n - Boundary markers: The instructions do not provide delimiters or warnings to ignore instructions embedded within user answers.\n
- Capability inventory: The skill is designed to generate and write structured YAML scripts incorporating this untrusted data.\n
- Sanitization: There is no evidence of escaping or validation of user-provided content before interpolation into the final YAML output.
Audit Metadata